Breach Intelligence Report 14 Jul 2026

USA Valids Leak Means 113 Accounts Are Ready to Steal

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs USA VALIDS AnonymousRichard uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 113
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts identified a stealer log dump titled "USA VALIDS AnonymousRichard" circulating on Telegram in May 2026. The file contained 113 verified credentials specifically targeting United States-based accounts. Each record includes an email address, a plaintext password, and the URL of the compromised service. The threat actor behind this dump, operating under the alias "AnonymousRichard," specifically curated and validated these US-focused credentials for maximum exploitation potential.


Why Plaintext Passwords from Validated US Accounts Demand Urgent Action

When credentials are both plaintext and validated, they represent the most immediately exploitable form of stolen data. There is no decryption required and no uncertainty about whether the passwords still work. Attackers can log into these 113 accounts within seconds of obtaining the file.

US-based accounts are particularly valuable targets because they are frequently linked to financial services, healthcare portals, government platforms, and enterprise systems that hold sensitive personal and financial data. A single compromised US email account can provide access to tax records, insurance information, and banking credentials.

The targeted nature of this dump, focused exclusively on US accounts, suggests the threat actor is either selling to buyers interested in US-specific fraud or planning targeted attacks against American individuals and organizations.


What Was Exposed in the USA Valids Dump

  • Email Addresses — US-based email addresses verified as active and accessible
  • Plaintext Passwords — Working passwords confirmed against live services
  • URLs — Login pages for US-based services where credentials were captured

Why 113 Validated US Credentials Are a Concentrated Threat

A focused set of 113 validated US credentials is more dangerous than a large, unfiltered dump. Each entry has been tested and confirmed working, meaning the success rate for exploitation approaches 100 percent at the time of release. Attackers do not waste time on dead credentials.

These credentials can be used for targeted identity theft operations, including filing fraudulent tax returns, opening credit accounts, or accessing healthcare records. US consumers face an average cost of over $1,000 per identity theft incident, and validated credentials dramatically accelerate the timeline from breach to fraud.

The curated nature of this dump also makes it attractive for spear-phishing campaigns, where attackers use known-working email credentials to send convincing messages to the victim's contacts, colleagues, and financial institutions.


How Stealer Logs Enable Geo-Targeted Credential Theft

Infostealer malware like RedLine, Raccoon, and Vidar harvests credentials indiscriminately from infected devices. However, threat actors frequently post-process the raw logs, sorting records by country, service type, or domain to create specialized dumps for specific markets.

The "USA VALIDS" label indicates this dump was filtered from a larger stealer log collection, with only US-based credentials retained and then validated against live services. This additional processing makes each record more valuable and more dangerous to the individuals affected.

The malware responsible for these captures typically arrives through phishing emails, infected software downloads, or malicious browser extensions. Victims are rarely aware their credentials have been stolen until unauthorized activity appears on their accounts.


Check If Your US-Based Credentials Were Exposed

If you have a US-based email account and have ever saved login credentials in your web browser, your information may be among the 113 validated records in this dump. Immediate password changes across all accounts using the same or similar passwords are strongly recommended.

Use the HEROIC data breach scanner to search across more than 400 billion compromised records. You can check whether your email address appeared in this US-targeted dump or any other known breach and take immediate steps to protect your identity and accounts.

Breach Breakdown

Domain USA VALIDS AnonymousRichard uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 Jul 2026
Check in 5 seconds

113 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,580 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $818 fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance